Offensive360 is a commercial SAST and DAST platform from O360 B.V., based in Amsterdam. Both scanners, plus mobile and attack surface modules, run from one virtual appliance that works fully offline.
The company says it was founded by offensive security professionals. It builds its scanning engines in-house rather than wrapping third-party tools, and it sells a custom annual license with no per-developer fee.

What is Offensive360?
Offensive360 is the application security brand of O360 B.V. The footer of its site lists the company as ISO/IEC 27001 certified.
The product line covers source code, running applications, mobile packages, container artifacts and external assets. AI Pentester and Autonomous Red Teaming run on the DAST engine. An early-access GRC module takes in scan evidence.
| Module | What it covers |
|---|---|
| SAST | Source analysis with taint and data-flow tracking; 60+ languages per the vendor, 15 language families in the knowledge base |
| Dependency, malware, license | Package advisories, malware and binary tampering, and license compliance, run alongside a SAST scan |
| DAST | Web apps and REST/GraphQL APIs; 40+ active checks, 19 passive analyzers, authenticated scanning |
| MAST | Android APK/AAB and iOS IPA binaries, mapped to the OWASP Mobile Top 10 (2024) |
| ASM | Subdomains, ports, services, TLS posture and breached credentials, with hourly or daily monitors |
| Container and IaC | Docker/OCI image archives, CycloneDX/SPDX SBOMs and Kubernetes manifests; Terraform, CloudFormation and Helm listed on the integrations page |
| AI Pentester / Red Teaming | Authorization-gated PTES engagements and scoped autonomous testing on the DAST engine |
| GRC (early access) | Risk register, audits and framework packs such as NCA ECC-2:2024, SAMA CSF and ISO/IEC 27001 |
Customer references are anonymized. The vendor lists sectors rather than names: healthcare, automotive, armed forces, banks, government, EU agencies and consulting firms.
What are Offensive360’s key features?
SAST with taint and data-flow analysis
The SAST engine models source code, follows untrusted input to sinks such as queries, file operations, templates and process calls, then applies security rules. Findings carry CWE and OWASP mapping plus remediation guidance.
The vendor quotes 60+ languages. The knowledge base is more specific and documents these source-language families:
| Language family | Typical inputs | Frameworks named by the vendor |
|---|---|---|
| C# / .NET | .cs, .cshtml, .aspx | .NET Framework, .NET Core |
| Java | .java, JSP | Spring, Struts, JEE |
| JavaScript / TypeScript | .js, .jsx, .ts, .tsx | Node.js, Express, React, Angular, Next.js, NestJS |
| Python | .py | Django, Flask, FastAPI |
| PHP | .php, .phtml, .inc | Laravel, Symfony, WordPress |
| Go / Ruby | .go, .rb, .ru | Gin, Echo, Rails, Sinatra |
| Kotlin / Swift / Objective-C / Dart | .kt, .swift, .m, .dart | Android, iOS, Flutter |
| C / C++ | .c, .cpp, .cc, headers | Systems and embedded code |
| Apex | .cls, .trigger | Salesforce |
| Oracle Forms / PL/SQL | Readable Forms exports, PL/SQL source | Oracle |
The vendor’s docs add two caveats. Oracle Forms needs readable exports, since parsing binary .fmb or .pll files is not documented.
A Rust secure-coding guide exists, but Rust is not among the documented SAST language families.

Dependency, malware and license checks
A scan result splits into four tabs: Vulnerabilities, Dependencies, Malware and License. The GitHub Action exposes each extra analysis as a separate input, all off by default.
Dependency analysis reads supported manifests and lockfiles.

Container and IaC checks
The container security product assesses uploaded Docker or OCI image archives, CycloneDX or SPDX SBOMs and Kubernetes manifests. It does not connect to live clusters or registries.
The integrations page also lists scanning for Dockerfiles, Helm charts, Terraform and CloudFormation. The vendor says availability and limits should be confirmed for each deployment.
DAST with headless crawling and 40+ active checks
The DAST engine renders JavaScript-heavy single-page apps in headless Chromium, discovers pages, forms and API calls, and then attacks each endpoint. Findings ship with the request and response that prove them.
| Check class | Examples from the vendor’s list |
|---|---|
| Injection | SQL (error, boolean, time-based), OS command, LDAP, XPath, NoSQL, expression language, SSTI, SSI |
| Cross-site scripting | Reflected, stored, DOM-based, client-side template injection, blind XSS confirmed out-of-band |
| Authentication and sessions | Session fixation, JWT misconfiguration and replay, password-reset poisoning, default credentials |
| Access control | IDOR/BOLA, BFLA, mass assignment tested against an 18-field dictionary of privileged attributes |
| Server-side and parsing | SSRF, XXE, insecure deserialization (Java, PHP, .NET, Python), path traversal, file upload |
| Protocol and infrastructure | Request smuggling, web cache poisoning, host-header, CRLF, prototype pollution, weak TLS |
| API | REST and GraphQL: introspection, BOLA, mass assignment, resource-consumption limits |
| AI and LLM apps | OWASP Top 10 for LLM Applications (2025): prompt injection, system prompt leakage, output handling |
Authenticated scanning supports form login, token and cookie sessions, multi-step flows and role-based testing.
Blind SSRF, XXE and XSS are confirmed through a self-hosted out-of-band callback service, so no third-party collaborator server is involved.
Safe mode is on by default and denial-of-service techniques are force-disabled in every mode. The vendor also says each engine release must produce zero findings against clean control applications before it ships.
Mobile and attack surface modules
MAST decompiles the APK, AAB or IPA you ship and checks secrets, storage, cryptography, network configuration and platform settings. Reports map to the OWASP Mobile Top 10 (2024) and export as PDF.
ASM starts from a seed scope of domains and emails. It enumerates subdomains, resolves hosts, checks ports, services and certificates, and correlates breached credentials, with change alerts on an hourly or daily cadence.
IDE plugins and the MCP server
IDE plugins cover VS Code, Visual Studio, IntelliJ, Android Studio and Eclipse. Each has its own repository under the Offensive360 GitHub organization.
The open-source MCP server gives Claude Code, Claude Desktop, Cursor and other MCP clients two tools.
o360_scan_path zips a local directory and returns findings with file, line, severity and fix. o360_scan_status reports queue position.
How does Offensive360 deploy on-premise and air-gapped?
Deployment is where Offensive360 differs most from SaaS-first scanners. SAST, DAST, MAST and ASM ship inside one virtual appliance, and targets, code and findings stay in your environment.
| Option | Delivery | What to confirm |
|---|---|---|
| Cloud | Hosted SaaS, same engine | Hosting location, data handling, retention, product availability |
| On-premise | OVA for your data center, or Azure VHD in your own tenant | Sizing, backup, upgrades, permitted network connections |
| Air-gapped | Same appliance with no internet access | Offline licenses, rule and advisory updates, integration limits |
The changelog dates the offline work. The August 31, 2026 release made all core language engines analyze fully offline, and Azure images carry a LUKS-encrypted payload with key release through a licensing relay.
What does Offensive360 integrate with?
The SAST product page lists GitHub Actions and a GitLab CI template as native options. Bitbucket, Azure DevOps, Jenkins and CircleCI connect through the REST API and a built-in setup wizard.
Jira tickets are created automatically with severity mapping, and webhooks cover other systems. Syslog forwarding to a SIEM was validated end to end with FortiSIEM, per the August 20, 2026 changelog entry.
How does the free SAST GitHub Action work?
Public repositories on GitHub, GitLab, Bitbucket or Codeberg can request a free scan token. Tokens usually arrive within one business day, last 30 days, and renew by replying to the issuance email.
The offensive360/sast-scan-action repository is MIT-licensed and was released in August 2026. This is the quick-start workflow from its README:
name: SAST
on:
push:
branches: [main]
pull_request:
permissions:
contents: read
security-events: write # only needed when upload-sarif is enabled
jobs:
sast:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: offensive360/sast-scan-action@v1
with:
api-url: https://sast.offensive360.com # or your own on-prem instance
api-token: ${{ secrets.O360_API_TOKEN }}
upload-sarif: 'true'
fail-on: high
| Input | Default | Purpose |
|---|---|---|
api-url | required | Base URL of the cloud or on-premise instance |
api-token | required | External scan token, stored as a repository secret |
fail-on | high | Fails the job at or above none, low, medium, high or critical |
upload-sarif | false | Sends results to the GitHub code scanning tab |
dependency-scan / malware-scan / license-scan | false | Adds SCA, malware and license analysis |
timeout-seconds | 3000 | Maximum wait for the scan |
The action zips the workspace and uploads it to the instance in api-url.
Large repositories can hit the cloud proxy’s time limit. The README suggests scanning a subdirectory or using your own instance.
The free program is SAST only and runs on a shared cloud instance. Scanning private or commercial code with an open-source token gets the token revoked.
Offensive360 vs Checkmarx
Checkmarx One is the broader platform. It bundles SAST, SCA, DAST, IaC, container, API security, secrets detection and ASPM, supports 150+ languages and technologies, and offers SaaS and self-hosted deployment.
Offensive360’s published portfolio covers SAST, SCA, DAST, MAST, ASM, container artifacts, AI-driven pentesting and early-access GRC. ASPM is not on that list.
What sets it apart is one offline appliance with in-house engines, licensed without counting developers.
Checkmarx quotes vary with developer count and scanner selection, according to my Checkmarx review. Offensive360 sizes its license by products and scan scope instead.
Pick Checkmarx if you need ASPM, 150+ languages and a long enterprise record from one vendor. Pick Offensive360 if an air-gapped SAST plus DAST appliance and seat-free licensing matter more.
Offensive360 vs Fortify
Fortify Static Code Analyzer is OpenText’s long-running enterprise SAST. It detects 1,700+ vulnerability categories across 33+ languages and 350+ frameworks, with on-premises, SaaS and hybrid options.
Fortify covers legacy languages such as COBOL and ABAP and has a two-decade record in government and defense. Offensive360 does not list COBOL or ABAP among its documented language families.
Offensive360 packages SAST and DAST in one offline appliance, delivered as an OVA or Azure VHD image, and offers free SAST for open-source projects.
Pick Fortify if legacy-language coverage or an established OpenText relationship drives the decision. Pick Offensive360 if you want SAST and DAST together in one fully offline appliance.
Offensive360 vs SonarQube
SonarQube pairs code quality with security. The free Community Build is self-hosted, paid Server editions reach 35+ languages, and Developer Edition starts at a published $750 per year.
SonarQube’s strength is quality gates and breadth across bugs, code smells and security. Taint analysis sits in the Enterprise edition, and SonarQube has no DAST.
Offensive360’s code analysis is security-focused. It adds taint-based SAST, runtime DAST, mobile binary analysis and offline operation.
SonarQube has the more developed code-quality and quality-gate offering, and Offensive360 publishes no price.
Pick SonarQube for quality plus baseline security with a public price list. Pick Offensive360 when you need SAST and DAST together inside an isolated network.
How much does Offensive360 cost?
Offensive360 publishes no list prices. Both plans on its pricing page are a “custom annual license”, and the page states there is no per-seat fee.
| Plan or program | Published price | What the vendor lists |
|---|---|---|
| Application Security (platform) | Custom annual license | SAST and DAST options, CI/CD integrations, team collaboration, scope agreed in proposal |
| On-Premise (enterprise) | Custom annual license | OVA appliance, air-gapped option, support terms and service levels in proposal |
| Open-source program | Free | SAST only, public repositories, 30-day renewable tokens |
| Evaluation | Free scans on request | Personalized demo and evaluation scans |
The About page describes an “unlimited scanning model” with no per-scan fees under one annual license. The Action README goes further and says “flat pricing, unlimited users and scans”.
The pricing page itself says scanning scope is agreed in the proposal. I would get the scope wording in writing before treating the license as unlimited.
How do you get started with Offensive360?
- Pick a path. Open-source maintainers request a free token on the free-for-open-source page. Commercial teams book the 30-minute demo or ask for evaluation scans.
- Choose a deployment. Use the cloud instance for a quick trial, or request the OVA or Azure VHD appliance if code cannot leave your network.
- Add a CI step. Drop in
offensive360/sast-scan-action@v1or the GitLab CI template, with the token stored as a secret andfail-onset to your gate. - Review and retest. Check skipped files and analyzer status in the scan summary, triage findings with their evidence, fix, and rescan.
When should you use Offensive360?
I would shortlist Offensive360 for regulated teams that cannot send code or scan traffic outside their network. Government, defense, banking and healthcare buyers needing SAST and DAST offline are the clearest match.
It also fits organizations with many developers and few security staff. Developer count is not the pricing metric, although product mix and scanning scope can change the quote.
It is a weaker fit if you need a code-quality program, an ASPM layer, or COBOL and ABAP coverage. Teams that want named customer references will find only anonymized sector lists.
For a primer on combining static and runtime testing, see SAST vs DAST vs IAST .
What are alternatives to Offensive360?
- Checkmarx One : enterprise platform with SAST, SCA, DAST, IaC, container, API and ASPM, in SaaS or self-hosted form.
- Fortify Static Code Analyzer : OpenText SAST with 33+ languages, strong legacy coverage and on-premises deployment.
- HCL AppScan : SAST, DAST, IAST and SCA suite offered in cloud, on-premises and desktop variants.
- SonarQube : self-hosted code quality and security with a free Community Build.
For broader lists, see Checkmarx alternatives , Fortify alternatives , or every reviewed tool in the SAST tools hub.
What are Offensive360’s limitations?
The language count needs checking. The vendor quotes 60+ languages, while the knowledge base documents 15 families, so ask for the analyzer matrix for your release.
The public footprint is small. The GitHub repositories had no stars when I reviewed them, customer references are anonymized, and the open-source Action dates only from August 2026.
One CI example conflicts with the repository. The integrations page uses offensive360/sast-action@v1 with different inputs from the offensive360/sast-scan-action README, so follow the README.
Container and IaC scope needs confirming. Container checks assess uploaded artifacts rather than live clusters, and the vendor says availability depends on the deployment.
Pricing needs a sales conversation. No figures are published, and the “unlimited” wording on some pages sits next to “agreed scan scope” on the pricing page.